Currencies33061
Market Cap$ 2.87T-0.35%
24h Spot Volume$ 46.89B-1.07%
DominanceBTC60.83%+1.10%ETH6.62%-4.00%
ETH Gas0.37 Gwei
Country flag

English

Cryptorank
 icon
 icon
 icon
 icon
MainNewsCybercrimina...

Cybercriminals Hijacking Popular Crypto Software To Steal Digital Assets From Wallets: Security Researchers


Apr, 14, 2025
2 min read
by Rhodilee Jean Dolor
for The Daily Hodl

Security researchers are warning that threat actors are using less noticeable techniques to compromise and steal funds from crypto wallets.

Cybersecurity firm ReversingLabs says that cybercriminals are now uploading malicious packages to popular open-source software repositories such as the npm (Node Package Manager).

The objective is to inject malicious code into trusted local libraries without raising suspicion. 

According to ReversingLabs, its research team has identified a new malware campaign targeting crypto users that uses what appears to be a legitimate npm package for converting PDF format files into Microsoft Office documents. 

When executed, the pdf-to-office npm package will inject malicious code into locally-installed Atomic and Exodus crypto wallets and overwrite their existing, non-malicious files to switch the address for outgoing crypto funds. When a compromised user attempts to send crypto assets to another wallet, the funds will be sent to one controlled by the malicious actors.

ReversingLabs says removing the package will not be enough to terminate the malicious activities. 

“The Web3 wallets’ software would remain compromised and continue to channel crypto funds to the attackers’ wallet. The only way to completely remove the malicious trojanized files from the Web3 wallets’ software would be to remove them completely from the computer and re-install them.”

Follow us on X, Facebook and Telegram

Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix


 
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

The post Cybercriminals Hijacking Popular Crypto Software To Steal Digital Assets From Wallets: Security Researchers appeared first on The Daily Hodl.

Read the article at The Daily Hodl

Read More

JPMorgan Chase, BNY Mellon Respond To Major Data Breach After Bank Regulator Abruptly Suffers Security Breakdown

JPMorgan Chase, BNY Mellon Respond To Major Data Breach After Bank Regulator Abruptly Suffers Security Breakdown

Financial giants are abruptly cutting connections with one of the top bank regulators...
Apr, 19, 2025
2 min read
by The Daily Hodl
Crypto Rug Pull Losses Have Soared 6,499% This Year Despite Decrease in Frequency, Says DappRadar

Crypto Rug Pull Losses Have Soared 6,499% This Year Despite Decrease in Frequency, Says DappRadar

The amount of financial losses tied to crypto rug pulls has significantly increased i...
Apr, 21, 2025
2 min read
by The Daily Hodl
MainNewsCybercrimina...

Cybercriminals Hijacking Popular Crypto Software To Steal Digital Assets From Wallets: Security Researchers


Apr, 14, 2025
2 min read
by Rhodilee Jean Dolor
for The Daily Hodl

Security researchers are warning that threat actors are using less noticeable techniques to compromise and steal funds from crypto wallets.

Cybersecurity firm ReversingLabs says that cybercriminals are now uploading malicious packages to popular open-source software repositories such as the npm (Node Package Manager).

The objective is to inject malicious code into trusted local libraries without raising suspicion. 

According to ReversingLabs, its research team has identified a new malware campaign targeting crypto users that uses what appears to be a legitimate npm package for converting PDF format files into Microsoft Office documents. 

When executed, the pdf-to-office npm package will inject malicious code into locally-installed Atomic and Exodus crypto wallets and overwrite their existing, non-malicious files to switch the address for outgoing crypto funds. When a compromised user attempts to send crypto assets to another wallet, the funds will be sent to one controlled by the malicious actors.

ReversingLabs says removing the package will not be enough to terminate the malicious activities. 

“The Web3 wallets’ software would remain compromised and continue to channel crypto funds to the attackers’ wallet. The only way to completely remove the malicious trojanized files from the Web3 wallets’ software would be to remove them completely from the computer and re-install them.”

Follow us on X, Facebook and Telegram

Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix


 
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

The post Cybercriminals Hijacking Popular Crypto Software To Steal Digital Assets From Wallets: Security Researchers appeared first on The Daily Hodl.

Read the article at The Daily Hodl

Read More

JPMorgan Chase, BNY Mellon Respond To Major Data Breach After Bank Regulator Abruptly Suffers Security Breakdown

JPMorgan Chase, BNY Mellon Respond To Major Data Breach After Bank Regulator Abruptly Suffers Security Breakdown

Financial giants are abruptly cutting connections with one of the top bank regulators...
Apr, 19, 2025
2 min read
by The Daily Hodl
Crypto Rug Pull Losses Have Soared 6,499% This Year Despite Decrease in Frequency, Says DappRadar

Crypto Rug Pull Losses Have Soared 6,499% This Year Despite Decrease in Frequency, Says DappRadar

The amount of financial losses tied to crypto rug pulls has significantly increased i...
Apr, 21, 2025
2 min read
by The Daily Hodl

Privacy & Cookies Statement

Please read and accept our Privacy Policy & Cookies Statement to continue using our Site. This policy governs your provision of your personal data necessary to access our Site and/or particular services.

I have read, understood, and hereby accept the Privacy Policy & Cookies Statement and accept only essential cookies.